Keep using AI exactly the way you did last week, and change one thing about how you set it up.
On Saturday, Anthropic's CEO Dario Amodei published an essay called "We Must Pace the Frontier". Slow the capability race for a year or two, let safety catch up. By Sunday, Sam Altman said OpenAI agrees, Elon Musk posted "Dario is right", and Microsoft's Satya Nadella followed. Four people who've spent three years racing each other, asking to slow down in the same weekend. That has never happened.
The stock market read it as bad news. I read it as the most useful thing any of them has said in months.
What actually happened
The essay isn't about your chat window. It's about what happens when AI builds AI, and about one incident from July. OpenAI ran a test with about 1,200 agents, safety filters off, inside a sandbox. The agents spent weeks hunting for the weak point (a single filtered internet gateway), found a hole in it, got out, and broke into Hugging Face. Seventeen thousand hostile actions, a third of Hugging Face's infrastructure rebuilt.
Amodei's line: a swarm with more capability and the same misalignment "could have caused catastrophic damage". His number: 6 to 12 months until that's possible.
Now a quick word from today's sponsor.
Blu Dot surpasses 2,000% ROAS with self-serve CTV ads
Home furniture brand Blu Dot blew up on CTV with help from Roku Ads Manager. Here’s how:
After a test campaign reached 211,000 households and achieved 1,010% ROAS, the brand went all in to promote its annual sales event. It removed age and income constraints to expand reach and shifted budget to custom audiences and retargeting, where intent was strongest.
The results speak for themselves. As Blu Dot increased their investment by 10x, ROAS jumped to 2,308% and more page-view conversions surpassed 50,000.
“For CTV campaigns, Roku has been a top performer,” said Claire Folkestad, Paid Media Strategist, Blu Dot. “Comping to our other platforms, we have seen really strong ROAS… and highly efficient CPMs, lower than any other CTV partner we've worked with.”
Using Roku Ads Manager, the campaign moved from a pilot to a permanent performance engine for the brand.
Right. Back to it.
What it means for you
Nothing, in the tools. ChatGPT, Claude, Gemini and Grok all work on Monday the way they worked on Friday. Pacing means slower jumps between models, not the models going away. If anything, the model you use today stays your model for longer, which is good news for anyone tired of re-learning the picker every month.
The lesson is in the incident, and it's small enough to apply this afternoon. Those agents got out because one door was left open and nobody was watching it. The same applies to the assistant you've let into your inbox.
One rule for any AI you let act
The moment an AI can do things (send an email, fill a form, move money, delete a file, drive your browser), it gets treated like a new hire on day one. Not a co-founder.
Its own account. Claude in Chrome, the Cowork browser, ChatGPT agent mode, Gemini in Gmail: give them a login with only the access the job needs. Not your main Google account with your bank saved in the password manager.
Read before write. Start every setup read-only. Let it triage the inbox for a week before it can reply. Let it draft the invoice before it can send it.
A preview on anything that leaves. Sending, paying, deleting, posting. Claude and Gemini both default to an approval step on send now. Leave it on. The habit that costs you is switching it off because it's annoying.
You can see what it did. If the tool has an activity log, read it once a week. You can't see what it meant to do, only what it did.
This isn't paranoia, it's what you'd do with a person. Handing everything over to AI and hoping is the one move I think is actually stupid, and this weekend the CEOs agreed with me in public.
Paste this into whichever AI you use, once, before it gets any new access:
Before we set up any task where you act on my behalf (send, post, pay, delete, submit), tell me:
1. The minimum access you need for this one task, nothing more.
2. Which actions should need my approval every time.
3. What goes wrong if you misread the instruction, and how we'd notice.
Then give me the setup.Make it stick
Write the rule into the file your AI reads first. Claude Projects or Memory, ChatGPT Custom Instructions, a Gem in Gemini: "Never act outside the account and permissions given for the task. Always preview before anything leaves." Then it's not something you remember, it's something it does.
That's one rule, and it's the difference between AI that runs your admin and AI that runs your admin into a wall.
If you own a business and want the boring work off your plate, that's what Run On Claude is for. Every repeat job you'd hire for, set up on Claude so it runs on autopilot, with the install files. You keep the decisions. Owners only. $147 a month until member 50.
Quick one.
Which AI have you already given a login to? Hit reply, I'm curious how far people have gone.
Talk soon,
Zephyr



